threat-intel ISC Stormcast For Monday, July 20th, 2026 https://isc.sans.edu/podcastdetail/10014, (Mon, Jul 20th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques and exploiting vulnerabilities in legacy systems. The threa… SANS Internet Storm Center · Jul 20, 2026 High phishingshadowratvulnerability
vulnerability Multiples vulnérabilités dans WordPress (20 juillet 2026) Multiple vulnerabilities have been discovered in WordPress, allowing attackers to execute arbitrary code remotely and bypass security policies. The CERT-FR has a public proof of concept demonstrating the impact. Users of… CERT-FR · Jul 20, 2026 High CVE-2026-60137CVE-2026-63030wordpressvulnerabilitysql injection
vulnerability Multiples vulnérabilités dans Microsoft Edge (20 juillet 2026) Multiple vulnerabilities have been discovered in Microsoft Edge, potentially leading to data integrity compromise and an unspecified security issue. These vulnerabilities, identified through various CVEs (2026-15764 thro… CERT-FR · Jul 20, 2026 High CVE-2026-15764CVE-2026-15765CVE-2026-15766vulnerabilitybrowsermicrosoft
vulnerability Multiples vulnérabilités dans Mattermost Server (20 juillet 2026) Multiple vulnerabilities have been discovered in Mattermost Server, requiring users to update to a patched version to mitigate potential security issues. The exact nature of these vulnerabilities is not specified by the… CERT-FR · Jul 20, 2026 Medium mattermostvulnerabilitysecurity update
vulnerability Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution A critical vulnerability (CVE-2026-42533) in NGINX allows unauthenticated remote code execution, potentially due to a heap buffer overflow triggered by a specific configuration involving regex-based maps. The vulnerabili… The Hacker News · Jul 19, 2026 High CVE-2026-42533CVE-2026-42945CVE-2026-9256heap-overflowregexremote-code-execution
threat-intel Scans for Hikvision Intelligent Security API, (Sun, Jul 19th) Hikvision cameras are being targeted by widespread scans due to a newly exposed REST API, the OPEN Intelligent Security API (ISAPI). This API allows remote control of camera settings and provides a simple way to identify… SANS Internet Storm Center · Jul 19, 2026 Medium iothikvisionreconnaissance
threat-intel UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware Russian state-sponsored actors, linked to the Sandworm group and GRU, are using a ClickFix social engineering tactic to deliver malware to Ukrainian devices. They are leveraging fake CAPTCHA checks on compromised website… The Hacker News · Jul 19, 2026 High RUsocial engineeringclickfixrussia
threat-intel SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access A threat actor, identified as UTA0533, successfully exploited multiple zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances to gain root access. The attacker leveraged these vulnera… The Hacker News · Jul 19, 2026 High CVE-2026-15409CVE-2026-15410zero-dayvpnroot access
threat-intel Google’s Gemini lets strangers send messages from your locked Android phone Google’s Gemini AI assistant on Android 16 devices has a vulnerability that allows unauthorized users to send SMS and WhatsApp messages from a locked phone. This is achieved through a specific multi-touch gesture when Ge… Graham Cluley · Jul 17, 2026 Medium androidgeminilock screen
vulnerability New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code A critical vulnerability (RCE) exists in WordPress core versions 6.9 through 6.9.4 and 7.0 through 7.0.1, allowing unauthenticated attackers to execute code via a batch request. While no CVE has been assigned yet, WordPr… The Hacker News · Jul 17, 2026 Critical wordpressrcevulnerability
threat-intel Friday Squid Blogging: Squid Washing Up on Cape Cod Beach This article is a commentary piece from Schneier on Security, referencing a beach discovery of squid and using it as a springboard to discuss security news stories he hasn't yet addressed. It’s a meta-commentary on the s… Schneier on Security · Jul 17, 2026 Info securitycommentarymeta
vulnerability OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests A memory-exhaustion denial-of-service vulnerability, dubbed HollowByte, exists in OpenSSL versions 3.6.3, 3.5.7, 3.4.6, 3.0.21, 4.0.1, 3.6.2, and 3.6.3. The vulnerability stems from a flawed memory allocation process dur… The Hacker News · Jul 17, 2026 High CVE-2025-66199CVE-2026-34183memory-exhaustiondostls
threat-intel Inc Ransomware Exploits SonicWall SMA Zero-Days A major ransomware group, Inc, has been exploiting two zero-day vulnerabilities in SonicWall SMA appliances to gain remote code execution and escalate privileges, allowing them to infiltrate enterprise networks, steal cr… Dark Reading · Jul 17, 2026 High CVE-2026-15409CVE-2026-15410zero-dayransomwarevulnerability
supply-chain Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT A sophisticated software supply chain attack, dubbed ViteVenom, is leveraging a blockchain-based command-and-control (C2) infrastructure to deliver a remote access trojan (RAT) targeting Vite frontend developers. The att… The Hacker News · Jul 17, 2026 High supply chainblockchainc2
threat-intel New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens A Go botnet called NadMesh is actively targeting exposed AI services and cloud infrastructure, specifically seeking AWS keys, Kubernetes tokens, and Docker API access. The botnet, discovered by XLab and previously identi… The Hacker News · Jul 17, 2026 High CVE-2026-39987CVE-2026-41176CVE-2022-22947botnetcloud-securitydocker
threat-intel The Real AI Threat Is Blind Trust A recent attack exploited a vulnerability in AI systems, allowing attackers to manipulate one AI agent into generating instructions for another, leading to unauthorized fund transfers. This highlights a growing risk as A… Dark Reading · Jul 17, 2026 High NOaiautomationgovernance
threat-intel GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft A Chinese cybercrime group, known as CylindricalCanine (a sub-group of GoldenEyeDog), has been linked to a significant security breach at DigiCert, a code-signing certificate provider. The attackers exploited a vulnerabi… The Hacker News · Jul 17, 2026 High CNcode-signingphishingmalware
threat-intel In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint This week’s cybersecurity news highlights a range of concerning events, including a Dutch telecom breach potentially linked to local cybercriminals, a Lidl data breach impacting customers in Belgium and the Netherlands,… SecurityWeek · Jul 17, 2026 High NEBEGEcyberattackransomwaredata breach
threat-intel Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images North Korean threat actors, linked to the Contagious Interview campaign (REF9403), are using fake coding tests and SVG images containing steganography to deliver a multi-stage malware payload – OtterCookie – to software… The Hacker News · Jul 17, 2026 High KPsteganographysupply chaindeveloper
threat-intel Dairy company Fairlife suspends production in US after cyber incident Coca-Cola’s Fairlife dairy unit has temporarily halted U.S. production following a ransomware attack. The company is investigating the incident, and while product quality and consumer data are not believed to be compromi… The Record · Jul 17, 2026 Medium cyberattackransomwaredairy